Password length limit for certificates in Kleopatra

VojtÄ›ch Zeisek <[email protected]> Fri, 12 Dec 2025 10:09:51 +0100
Newsgroups gmane.comp.kde.users.pim
Organization openSUSE GNU/Linux
Message-ID <2284026.hkbZ0PkbqX@svarog>
--nextPart1930001.LH7GnMWURc
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="utf-8"; protected-headers="v1"
From: =?UTF-8?B?Vm9qdMSbY2g=?= Zeisek <[email protected]>
To: KDE-PIM Users <[email protected]>
Subject: Password length limit for certificates in Kleopatra
Date: Fri, 12 Dec 2025 10:09:51 +0100
Message-ID: <2284026.hkbZ0PkbqX@svarog>
Organization: openSUSE GNU/Linux
MIME-Version: 1.0

Hi,
I need to use personal PKCS#12 certificates for signing mails in KMail, and=
 I=20
found one "funny" issue. Kleopatra has hard-coded limit of maximal password=
=20
length of 31 characters, well it's hard-coded in gpgsm from GnuPG [1], whic=
h=20
is the only tool to work with these certificates available for KDE PIM. I=20
usually work with longer passwords, so this limit is bi annoying, and seems=
=20
outdated as IDK any other recent tool with such a limit. Of course, I know =
I=20
can "repack" the certificate and shorten the password using OpenSSL, but st=
ill,=20
I wonder if there is any chance to get rid of this limit, either by updatin=
g=20
the GnuPG, or if KDE PIM would use (also) another library to work with=20
certificates (GnuTLS)...?
Yours,
V.

[1] <https://github.com/gpg/gnupg/blob/master/sm/minip12.c#L340>

=2D-=20
Vojt=C4=9Bch Zeisek
https://trapa.cz/

Komunita openSUSE GNU/Linuxu
Community of the openSUSE GNU/Linux
https://www.opensuse.org/

--nextPart1930001.LH7GnMWURc
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part.
Content-Transfer-Encoding: 7Bit

-----BEGIN PGP SIGNATURE-----

iQJPBAABCAA5FiEES97LYVdqIgW2UhmwtBndlZHSOVEFAmk7298bFIAAAAAABAAO
bWFudTIsMi41KzEuMTEsMiwyAAoJELQZ3ZWR0jlRz5QP/2zwNREWq397WvWI7Ner
V6jsmm52pLXSj+18T1BWmwd+3sr+HBYCjE4VqaYqKj+bPovEiI0PjLGl7sGVmSRw
Gtp2end6OZggQf76VY765Ut446WFYS5G/rwYhU2hzT+4lJrQMl+/nz03WmN+aUY5
dkZ6BkGIu29AmVxDrTMKqjNzgQ/zByEsWLq0KSS6xbdM51IjHwJbBJkKzDQloq1r
G/9aktz1t8/CoYlA2l/LsViMuQgrQyPbhXWDuAY+42rmjb+rkzsEb3PIC6mIMOgX
UpXE+n2uwrxc3zYcHYCNdb5s/je/UTLogz8yRghI+Tf0MnXYJsobwOkLRw9qcOpq
GdJ/dNT+MVI9INQkCeg0rA6fMjcZWKMk1aWyGFW2Urg0JwqXDCeznFvdKElP/2vO
v1Wc+iL9Lb0dCe4XF71iBrUbtP2JuBce61IQXbARxk5uk18WcFZ0B9Jckemx9vFw
MSBaKs89r5sMMQOtBsKSNzPo6Ko7L4Lkaok1BumCQ9mrBBbL6L4YSQ09q7mJyAty
X+pjxjR7I2tO4Kq2Epmubg5K3VO0Q1M2XpWVL4t7uZ3e9sSvARndIGL5nYR2wXAV
9EowqQsobWtgefCig8bh+u3JiSeTbBQt+kNMVBiCPewMc3n/yp/b3IkdJuy5j35r
1Qmo4duH+pjvT+SB8+z7OgtI
=F7Qb
-----END PGP SIGNATURE-----

--nextPart1930001.LH7GnMWURc--